How do I find a task I believe is related to coinminer malware? Solved

Page 2 of 2 FirstFirst 12
  1. Try3's Avatar
    Posts : 1,862
    Windows 10 Home x64 and Pro x86
       #11

    Platypus,

    Your case might be different but my unknown task did not appear in NirSoft's TaskSchedulerView or anywhere else except that task summary page you posted a diagram of.

    I don't know how we could use Process monitor to track things down either. I've used Process monitor for other things but can't see how to use it for this particular job.

    Denis
      My ComputerSystem Spec

  2. Callender's Avatar
    Posts : 1,335
    Windows 10 Home 1809 32-bit
       #12

    Try3 said: View Post
    I don't know how we could use Process monitor to track things down either. I've used Process monitor for other things but can't see how to use it for this particular job.
    Denis
    It creates a log of everything that ran on boot. Then open the log and check it.
    @PlatypusKnight

    As you seem to be using an HP machine check this out:

    HP Comm Recovery - HP Support Community - 6598136
      My ComputerSystem Spec

  3. Callender's Avatar
    Posts : 1,335
    Windows 10 Home 1809 32-bit
       #13

    I guess that if you can find a service - HP Connection Optimizer - then you could temporarily disable it to test.

    https://www.shouldiremoveit.com/HP-C...5-program.aspx
      My ComputerSystem Spec

  4. Try3's Avatar
    Posts : 1,862
    Windows 10 Home x64 and Pro x86
       #14

    Do bear in mind that the unknown task and the signtool thing might be unrelated.

    I agree with Callender that Process monitor is appropriate for tracking down the source of the signtool thing.
    [My earlier, "I don't know how we could use Process monitor to track things down" comment was because I was thinking about the unknown task and had forgotten about the signtool thing.]

    Denis
      My ComputerSystem Spec

  5.    #15

    You guys are the best.
    Indeed signtool.exe was unrelated to the malware.
    I still don't know what those tasks are.
    Signtool.exe was related to HP Comm Recovery - HP Support Community - 6598136

    Thank you Callender.

    Try3 that Nirsoft tool is fantastic.

    This is why I come here.

    Marking this as solved.

    edit: spellings
      My ComputersSystem Spec


 
Page 2 of 2 FirstFirst 12

Related Threads
On my Win 10 Pro 64-bit Version 1803 machine with 16GB RAM and an i5 Intel chip, I like Task Manager to start automatically on startup. 1) If I put its shortcut in the Startup folder, nothing happens. 2) If I create a TaskScheduler task for it, to...
Read more: New XBash malware combines ransomware, coinminer, botnet, and worm features in deadly combo | ZDNet Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows - Palo Alto Networks Blog
Every...i mean every anti malware blocked by unknown malware/virus in AntiVirus, Firewalls and System Security
i have looked up this issue and apparently this must be a new one since there is no solution what so ever, even the hidden admin account is defenseless, here is what's going on 1. the PC got infected on windows defenders watch, the infection...
Unknown User accounts appearing (malware related??) in User Accounts and Family Safety
Hello, Today I discovered strange account names on my laptop after trying to open files on one of my drives which also had strange names and were not mine. I suspect my laptop is infected with some kind of malware but unfortunately all scans...
Is there a way to make the "Command Prompt" window show when I have a task running in Windows task Scheduler? I would like to be able to view the progress of the task. For example, I have a program called "Zap2xml" that collects TV EPG data. It...
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd
All times are GMT -5. The time now is 09:13.
Find Us